Legal
Privacy Policy
Last updated 5 July 2026
This Privacy Notice for MilUX Ltd ("we", "us", or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
- Visit our website at https://milux.co.uk/, or any website of ours that links to this Privacy Notice.
- Engage with us in other related ways, including any sales, marketing, or events, or when we hold your professional contact details as part of running our consultancy.
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at contact@milux.co.uk.
Summary of key points
- What personal information do we process? When you visit, use, or navigate our Services, or engage with us professionally, we may process personal information depending on how you interact with us. See "What information do we collect?" below.
- Do we process any sensitive personal information? We do not seek or knowingly process special category information such as racial or ethnic origin, sexual orientation, or religious beliefs.
- Do we collect information from other sources? Yes. For business development and relationship management, we collect professional contact information from public sources such as LinkedIn, company websites, Companies House, and gov.uk.
- Do we use AI or automated processing? We use AI-assisted tools to help run our consultancy. We do not make decisions about you by solely automated means that have a legal or similarly significant effect, and a person reviews consequential outputs.
- How do we process your information? To provide, improve, and administer our Services, communicate with you, develop business relationships, for security, and to comply with law.
- When and with whom do we share personal information? With the service providers (processors) that run our systems, and in specific situations described below.
- How do we keep your information safe? We have organisational and technical measures in place, though no system can be guaranteed completely secure.
- What are your rights? Depending on where you are, applicable privacy law may give you rights over your personal information.
- How do you exercise your rights? By submitting a data subject access request, or by contacting us. We act on requests in accordance with data protection law.
Table of contents
- What information do we collect?
- How do we process your information?
- What legal bases do we rely on?
- Do we use AI or automated processing?
- When and with whom do we share your personal information?
- Do we use cookies and other tracking technologies?
- How do we handle your social logins?
- International transfers of your information
- How long do we keep your information?
- How do we keep your information safe?
- Do we collect information from minors?
- What are your privacy rights?
- Controls for do-not-track features
- Do we make updates to this notice?
- How can you contact us about this notice?
- How can you review, update, or delete the data we collect from you?
1. What information do we collect?
Personal information you disclose to us
In short: we collect personal information that you provide to us.
We collect personal information that you voluntarily provide when you express an interest in us or our Services, participate in activities, or otherwise contact us. Depending on the context, this may include: names, email addresses, job titles, organisation, contact preferences, billing addresses, and contact or authentication data.
Sensitive information. We do not seek or knowingly process sensitive (special category) information.
Payment data. If you make a purchase, we may collect data necessary to process your payment, such as your payment instrument number and security code. Payment data is handled and stored by Stripe, PayPal, and Ticket Tailor. Their privacy notices are athttps://stripe.com/gb/privacy,https://www.paypal.com/myaccount/privacy/privacyhub, andhttps://www.tickettailor.com/legal/privacy-policy.
Information we collect from public sources
In short: we collect professional contact information from public sources to develop and manage business relationships.
MilUX is a business-to-business consultancy. As part of business development and relationship management, we collect and hold professional information about people in our sector from publicly available sources, such as LinkedIn profiles, company websites, Companies House, gov.uk, public event listings, and published articles. This typically includes name, employer, role, professional background, and publicly listed contact details. We hold this in our customer relationship management (CRM) records.
We process this information on the basis of our legitimate interests in running and growing the consultancy, balanced against your interests and rights. You can object to this processing at any time using the contact details below.
Information automatically collected
In short: some information, such as your IP address and browser characteristics, is collected automatically when you visit our Services.
We automatically collect certain information when you visit our website. This does not reveal your specific identity but may include device and usage information, such as IP address, browser and device characteristics, operating system, language preferences, referring URLs, country and approximate location, and information about how and when you use our Services. We collect this to maintain the security and operation of our Services and for internal analytics and reporting, including through cookies and similar technologies.
2. How do we process your information?
In short: to provide, improve, and administer our Services, communicate with you, develop business relationships, for security, and to comply with law.
We process your personal information to:
- Respond to your enquiries and provide support.
- Deliver and manage our Services to you.
- Manage business relationships and business development, including holding professional contact records.
- Send administrative information, such as changes to our terms and policies.
- Fulfil and manage orders, payments, and related matters.
- Send marketing and promotional communications in line with your preferences. You can opt out at any time.
- Request feedback and contact you about your use of our Services.
3. What legal bases do we rely on?
In short: we only process your personal information when we have a valid legal reason to do so.
The UK GDPR and the EU GDPR require us to explain the lawful bases we rely on. Depending on the processing, we rely on:
- Consent. Where you have given us permission to process your information for a specific purpose, such as certain marketing. You can withdraw consent at any time.
- Performance of a contract. Where processing is necessary to deliver our Services to you, or to take steps at your request before entering a contract.
- Legitimate interests. Where processing is reasonably necessary to achieve our legitimate business interests and those interests are not overridden by your rights. This includes managing business relationships, holding professional contact records gathered from public sources, business development, and understanding and improving how our Services are used.
- Legal obligations. Where processing is necessary to comply with the law, such as accounting and tax record-keeping, or responding to a lawful request from a public authority.
4. Do we use AI or automated processing?
In short: we use AI-assisted tools to help run our consultancy. We do not make decisions about you by solely automated means with a legal or similarly significant effect, and a person reviews consequential outputs.
We use AI-assisted software to help us manage information, draft and organise communications, research our market, and run day-to-day operations more efficiently. Where these tools process personal information, they do so on our behalf as processors under our instructions, and they are covered by the same safeguards as our other service providers (see "When and with whom do we share your personal information?").
We do not make decisions about you that produce legal effects or similarly significant effects by solely automated means. A person remains responsible for, and reviews, any consequential output before it is acted on. We apply internal controls so that personal information read from one source is not routed to another without authorisation, and so that automated tasks do not send your information externally on their own initiative.
If you have questions about how we use these tools in relation to your personal information, contact us using the details below.
5. When and with whom do we share your personal information?
In short: we share information with the service providers that run our systems, and in specific situations described here.
Service providers (processors). We share personal information with third-party vendors and service providers that perform services for us and need access to do so. We put appropriate agreements in place with them. These include providers of:
- Email, calendar, and file storage.
- Notes, knowledge management, and work coordination.
- Messaging and customer relationship management.
- AI-assisted tooling.
- Scheduling and booking.
- E-signature and contract execution (for example NDAs and service agreements).
- User-research tools, where you take part in research we run.
- Accounting and payments (including Stripe, PayPal, and Ticket Tailor).
- Website hosting, transactional email, forms, and analytics.
We keep a current internal record of the providers we use and what each can access, and we assess any change before we make it.
Business transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business.
With your direction or consent. We may share your information where you direct us to, or where you have otherwise consented.
Legal requirements. We may disclose your information where required to do so by law, or to protect our rights, your safety, or the safety of others.
6. Do we use cookies and other tracking technologies?
In short: we may use cookies and similar technologies to collect and store information.
We use cookies and similar technologies only with your consent, apart from those strictly necessary for the site to work. Consent is collected and managed through CookieYes, the consent banner you see on your first visit. Your choice is stored so we do not ask on every visit, and the banner asks again when the stored choice expires (after twelve months) or when our use of cookies changes.
Analytics. With your consent, we use Google Analytics 4 (GA4) to understand how our website is used: which pages are visited, how visitors arrive, and how the site performs. We use this to improve the site. The lawful basis is your consent (UK GDPR Article 6(1)(a)); no analytics runs and no analytics cookie is set until you accept the analytics category in the banner, and nothing is sent to Google beforehand. GA4 does not log IP addresses, and Google retains event-level data for a limited period of at most fourteen months before deletion. For more on Google's practices, seehttps://policies.google.com/privacy.
Consent management. CookieYes records your consent choice (the categories you accepted or declined, and when) so we can honour and evidence it. You can change or withdraw your consent at any time using thecookie settings link, or the revisit icon on any page; withdrawing consent stops analytics from that point on.
7. How do we handle your social logins?
In short: if you register or log in using a social media account, we may receive certain profile information about you.
If you choose to register or log in using your social media account details, we may receive profile information from that provider, which often includes your name, email address, and profile picture. We use it only for the purposes described in this notice or made clear to you. We do not control how your social media provider processes your information; review their privacy notice for details.
8. International transfers of your information
In short: some of our service providers are located outside the United Kingdom.
We are based in the United Kingdom. Some of the service providers we rely on process personal information outside the UK, including in the United States. Where we transfer personal information outside the UK, we take steps to ensure an appropriate level of protection, for example by relying on a country the UK considers adequate, or on the UK International Data Transfer Agreement or Addendum and other appropriate safeguards. You can ask us for more detail about the safeguards we use by contacting us.
9. How long do we keep your information?
In short: we keep your information only as long as necessary.
We keep your personal information for as long as necessary for the purposes set out in this notice, unless a longer period is required or permitted by law (such as tax and accounting requirements). When we no longer have a legitimate need to process it, we delete or anonymise it, or, where that is not immediately possible, securely store and isolate it until deletion is possible.
10. How do we keep your information safe?
In short: we aim to protect your personal information through organisational and technical measures.
We have implemented appropriate and reasonable technical and organisational security measures designed to protect the personal information we process, including access controls, secure credential storage, endpoint protection, and network controls. However, no method of transmission over the internet or storage is completely secure, so we cannot guarantee absolute security. Transmission of personal information to and from our Services is at your own risk.
11. Do we collect information from minors?
In short: we do not knowingly collect data from or market to children under 18.
We do not knowingly collect, solicit data from, or market to children under 18, nor knowingly process such data. By using the Services, you represent that you are at least 18, or that you are the parent or guardian of a minor and consent to their use of the Services. If we learn that we have collected personal information from a person under 18, we will take reasonable steps to delete it. If you believe we may have any such data, contact us atcontact@milux.co.uk.
12. What are your privacy rights?
In short: you may have rights that give you greater access to and control over your personal information.
Under UK and EU data protection law you may have the right to: request access to and a copy of your personal information; request correction or erasure; restrict or object to processing; and, where applicable, data portability. You also have rights in relation to automated decision-making, though as set out above we do not carry out solely automated decision-making with legal or similarly significant effect. To exercise any of these rights, contact us using the details below.
If you believe we are unlawfully processing your personal information, you have the right to complain to the Information Commissioner's Office (ICO) athttps://ico.org.uk/, or to your local supervisory authority in the EEA.
Withdrawing your consent. Where we rely on your consent, you can withdraw it at any time by contacting us. This will not affect the lawfulness of processing before withdrawal.
Opting out of marketing. You can unsubscribe at any time using the link in our marketing emails or by contacting us. We may still send you service-related messages.
13. Controls for do-not-track features
Most browsers and some mobile systems include a Do-Not-Track ("DNT") feature. No uniform technology standard for recognising DNT signals has been finalised, so we do not currently respond to them. If a standard is adopted that we must follow, we will update this notice.
14. Do we make updates to this notice?
In short: yes, we update this notice as necessary to stay compliant with relevant laws.
We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Last updated" date. If we make material changes, we may notify you by prominently posting a notice or by contacting you directly.
15. How can you contact us about this notice?
If you have questions or comments about this notice, you may contact our data protection contact by email at contact@milux.co.uk, by phone at 01264 604948, or by post at:
MilUX Ltd, The IncuHive Space, 4th Floor Chantry House, The Chantry Centre, Andover, Hampshire, SP10 1LZ, England.
16. How can you review, update, or delete the data we collect from you?
You have the right to request access to the personal information we hold about you, details of how we have processed it, correction of inaccuracies, or deletion of your personal information. You may also have the right to withdraw consent where we rely on it. These rights may be limited in some circumstances by applicable law. To make a request, submit a data subject access request or contact us using the details above.